Improper Authentication in nginx-ui - #VU142582
Published: August 14, 2026
Vulnerability details
The vulnerability allows a remote user to take over accounts persistently.
The vulnerability exists due to improper authentication in the TOTP and passkey enrolment endpoints when handling requests with only a valid JWT. A remote user can bind an attacker-controlled TOTP secret or register passkeys for the current user to take over accounts persistently.
Exploitation requires a stolen valid JWT for the victim account and affects users who have not yet enabled TOTP, while passkey registration can be performed multiple times.